Comment Re:Crappy IT security has consequences (Score 2) 76
So much of security comes down to the authority to say no by the security team. When that happens things can be very secure for much less money spent. When companies realize that making things secure very frequently diverges from making people happy, then there can be security. So with that said, why the FUCK does this equipment even need to be connected? It should be air gapped and PLC programming laptops and others should also be sequestered and kept offline and free from any pluggable drives as well. But even with that said, most of the time issues come from C level. They are the ones that refuse to be told they can't do things on company equipment. I worked for a company that fell under DHS chemsec level 2, and even with those requirements they refused to do what the requirements said and the government was toothless for any ramifications for not doing it. When people grow a spine and start setting security to the absolute bare minimums necessary for specific company usage, then security things will keep happening. Again security is surprisingly easy when you run systems as pure whitelist and only for vetted and confirmed business need rather than letting people do whatever the fuck they want to.